Title :
Security audit of data flows across enterprise systems and networks
Author :
Joukov, Nikolai ; Shorokhov, Vladislav ; Tantsuyev, Dmytro
Author_Institution :
ModelizeIT Inc., NY, USA
Abstract :
Enterprise IT environments are heterogeneous and complex with dozens of important software components running on each server and exchanging data with other servers, point of sale terminals, kiosks, door locks, workstations, and other systems. It is necessary to identify and document critical data flows across these systems and networks and create and verify corresponding security perimeters. Thus, newly adopted payment card industry data security standard version 3 requires data flows documentation across systems and networks, which is hard to maintain manually. In this paper, we describe the design of an automated and scalable data flows identification and diagramming system that relies on practical information sources and software and hardware models. As a result, the system can be used for real-life security audit and planning projects in diverse real-life environments. We evaluate it in three enterprise IT environments that belong to various types of industries.
Keywords :
electronic data interchange; financial data processing; security of data; critical data flow documentation; critical data flow identification; data exchange; data flow security audit; diagramming system; enterprise IT environments; enterprise networks; enterprise systems; hardware models; information sources; payment card industry data security standard version 3; security perimeters; software components; software models; Databases; Decision support systems; Documentation; Network topology; Security; Servers; Software; Cardholder Data Environment (CDE); Payment Card Industry Data Security Standard v. 3 (PCI DSS v. 3); Security audit; dataflows across systems and networks; security planning;
Conference_Titel :
Internet Technology and Secured Transactions (ICITST), 2014 9th International Conference for
Conference_Location :
London
DOI :
10.1109/ICITST.2014.7038813